Skip to content
e12.mediaBack to the home page
← Back to the home page
Legal

Privacy Policy

This page explains what personal data is processed when you visit our website or get in touch with us.

Last updated: 9 September 2026
On this page
  1. Controller
  2. Hosting and access logs
  3. Cookies and analytics
  4. App catalogue
  5. Newsletter
  6. Contact by email
  7. External links
  8. Your rights

1. Controller

The controller responsible for processing personal data on this website is:

Waldemar Friesen
trading as e12.media
Eichweg 12
71254 Ditzingen
Deutschland
Email: legal@e12.media

2. Hosting and access logs

This website is delivered as a static site through Appwrite Sites. The provider is Appwrite Code Ltd. The Appwrite project is located in the Frankfurt region; pages and static files may be served from a network location close to you via the Appwrite Network.

Every visit processes technically necessary connection data. This can include in particular your IP address, date and time, the requested path, HTTP method and status code, response time, and browser and header information contained in the request. Appwrite creates access logs for page views and retains them for seven days on the Pro plan. We do not keep any of our own longer-term access logs.

This processing is necessary to deliver the website, ensure its stability and security, and investigate technical faults. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure and reliable operation of this information service.

Appwrite processes this data as our processor. Where data is processed outside the European Economic Area in connection with hosting or support, Appwrite relies on appropriate safeguards such as adequacy decisions and the European Commission’s Standard Contractual Clauses. Further information is available in Appwrite’s privacy policy.

3. Cookies and analytics

As currently implemented, this website does not set cookies and does not use comparable technologies to store or read information on your device permanently. The language you see is determined by the URL you visit and is not stored in a cookie or in your browser.

We do not use marketing or advertising trackers, do not build user profiles, and do not load web fonts from external providers. There is no contact form, no user account, and no payment function on this website.

For anonymous analytics, we use the open-source software Umami, which we operate ourselves — on our own server set up specifically for this purpose, not through Appwrite or any other third party. Umami works without cookies and without an identifier that is valid across multiple websites. For every page view, we record: the path requested, the referring domain of any link that brought you here, campaign parameters if they are present in the URL, and technical page-load metrics. For every session, we additionally record browser, operating system, device type, screen size, language, and an approximate location at country, region, and city level. Your IP address is used briefly for this purpose but is not stored in our database — we verified this against the database schema actually in use, not merely against the software’s own description.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is understanding which content and products attract interest, without identifying or profiling individual people. This data is automatically deleted after 180 days.

The underlying server infrastructure is operated by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, acting as our processor. The server itself is located in a Hetzner data centre in Helsinki, Finland, and therefore within the European Union.

4. App catalogue for e12.media apps

Individual e12.media apps can optionally open a “More apps” area. To do so, they request a small status record and a static product catalogue from this website. An app checks the status at most once every 24 hours while in the foreground; opening the area loads the catalogue. No account, movement, habit, reminder, or advertising identifiers are transmitted in the process. We do not attach campaign parameters and do not combine these requests into user profiles.

Technically, the same connection and access logs arise as for a normal page view, in particular the IP address and the requested path. Section 2 applies for purpose, legal basis, recipients, and retention. Each app’s core functionality remains usable without this request.

5. Optional newsletter

The controller for this newsletter is Waldemar Friesen, trading as e12.media, Eichweg 12, 71254 Ditzingen, Germany. You can contact us about privacy at legal@e12.media.

If you voluntarily subscribe to our newsletter, we process your email address, chosen language, the topics you explicitly select, the published version of the consent wording, and the times and states of signup, confirmation, changes and unsubscribe actions. Confirmation, preference, export, deletion and unsubscribe links contain random tokens that are technically required. We do not ask for your name and do not receive an app, device, installation or campaign identifier.

We use this data only to send updates for the topics you confirmed, keep a record of your consent, manage your preferences, and prevent further delivery attempts after a hard bounce or complaint. Signup, double opt-in and delivery are based on your consent under Article 6(1)(a) and Article 7 GDPR and on the prior express consent required for email marketing by section 7(2)(2) of the German Act Against Unfair Competition. Abuse prevention, the limited consent record, and bounce or complaint suppression are based on Article 6(1)(f) GDPR. Our legitimate interests are a secure service, defending against unfounded claims, protecting deliverability, and avoiding unwanted repeat deliveries.

After signup, we initially send only a confirmation email. Your selected topics are enabled only after you open its link. A change of language or confirmed topics may require another confirmation; until then, your previous confirmed settings remain active. You can remove individual topics in your preferences or unsubscribe completely at any time. Every newsletter contains links for both. Withdrawal applies for the future and does not affect the lawfulness of earlier processing. A later voluntary signup always requires a new double opt-in.

The platform runs listmonk and PostgreSQL on a cloud server managed by us and provided by Hetzner Online GmbH in Helsinki. listmonk and PostgreSQL are self-hosted software and are not additional recipients. Amazon Web Services EMEA SARL processes confirmation and newsletter messages through Amazon SES in the Frankfurt Region and the necessary bounce, complaint and reject events through Amazon SNS. The message is delivered to the email provider chosen by you. Encrypted PostgreSQL backups are stored with Appwrite Code Ltd. in its Frankfurt Region; files are encrypted with age before upload, and Appwrite does not hold the decryption key.

Depending on your email address and provider, delivery may require processing outside the European Economic Area. AWS incorporates the applicable Standard Contractual Clauses into its terms for relevant international transfers. Where Appwrite processing takes place outside the European Economic Area, Appwrite provides safeguards such as an adequacy decision or the European Commission's Standard Contractual Clauses, as applicable.

The newsletter application does not store your raw IP address, email address, tokens or message contents in access or application logs. Your IP address is technically transmitted when you connect and is held only briefly in memory for rate limiting. The Appwrite access logs described in the website hosting section also apply when the static website is loaded.

Unconfirmed signups are deleted after 30 days. Active signup data is kept until you fully unsubscribe, withdraw your consent or make a valid deletion request. We generally retain the minimum record of consent and withdrawal, and any necessary hard-bounce or complaint suppression entry, until the end of the third calendar year after the last relevant event, unless a specific legal matter requires longer retention. Recipient-level delivery and error events are generally deleted after 90 days unless they are needed for that minimum record or suppression entry.

Encrypted backups follow a rotation of daily, weekly and monthly restore points and are kept for up to 12 months. Data already deleted from the live system may remain in a backup until that backup expires. If a backup is restored, later deletions, unsubscribes and suppressions are applied again. We do not use open or click tracking, automated decision-making or profiling.

For access, correction, data portability, restriction, deletion, withdrawal or objection, contact legal@e12.media. You may also lodge a complaint with a competent data protection authority.

6. Contact by email

If you contact us by email, we process your email address, the content of your message, and any further information you choose to include. We use this data to handle your enquiry and to communicate with you.

Where a contract or a pre-contractual enquiry is involved, the legal basis is Art. 6(1)(b) GDPR. For general enquiries we rely on Art. 6(1)(f) GDPR; our legitimate interest is responding appropriately. Retention required by law is based on Art. 6(1)(c) GDPR.

Our email communication runs through Microsoft 365. The recipient acting as our processor is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. For European business customers, Microsoft 365 generally falls under the EU Data Boundary; limited transfers outside the EU and EEA can still occur for individual operational, security, or support processes. Microsoft uses the safeguards described in the Microsoft Data Protection Addendum for this purpose.

We delete enquiries once they have been fully handled and no contractual, legal, or legitimate grounds for further retention exist. Business and tax-relevant correspondence is kept for the statutory retention periods that apply. Further information is available in Microsoft’s privacy statement.

7. External links

Our website and the app catalogue contain links to external services, in particular to GitHub and to the official app pages of Apple and Google. Only once you open such a link does your browser or device connect to that provider. That provider is responsible for any processing that happens there.

8. Your data protection rights

Subject to the statutory requirements, you have the right to:

  • access the personal data we process about you,
  • rectification of inaccurate or incomplete data,
  • erasure or restriction of processing,
  • data portability,
  • object to processing based on Art. 6(1)(f) GDPR, and
  • withdraw any consent given, with effect for the future.

To exercise your rights, reach us at legal@e12.media. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the place where you usually live, where you work, or where the alleged infringement occurred.

9. Provision of data and automated decisions

The technical connection data is required to load the website. Any information you include in an email is provided voluntarily; without a reachable sender address, however, we cannot reply to you. We do not use automated decision-making or profiling.

10. Changes to this privacy policy

We update this privacy policy whenever the website, the services we use, or legal requirements change. The version published on this page applies.

ImprintPrivacy
© 2026 e12.media.